Vulnerability Description
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no wlan filter mac address WORD descript WORD' command template.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siretta | Quartz-Gold Firmware | g5.0.1.5-210720-141020 |
| Siretta | Quartz-Gold | - |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1613ExploitTechnical DescriptionThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1613ExploitTechnical DescriptionThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1613
FAQ
What is CVE-2022-41030?
CVE-2022-41030 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to a...
How severe is CVE-2022-41030?
CVE-2022-41030 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-41030?
Check the references section above for vendor advisories and patch information. Affected products include: Siretta Quartz-Gold Firmware, Siretta Quartz-Gold.